Описание
A security issue was found in Netplex Json-smart 2.5.0 through 2.5.1. When loading a specially crafted JSON input, containing a large number of ’{’, a stack exhaustion can be trigger, which could allow an attacker to cause a Denial of Service (DoS). This issue exists because of an incomplete fix for CVE-2023-1370.
A flaw was found in the JSON-smart library. In affected versions, specially crafted JSON input may trigger stack exhaustion, potentially leading to an application crash or denial of service. This issue exists due to an incomplete fix for CVE-2023-1370.
Отчет
This issue exists because of an incomplete fix for CVE-2023-1370, therefore it only affects json-smart v2.5.0 through v2.5.1 (inclusive).
Меры по смягчению последствий
Red Hat Product Security does not have a recommended mitigation at this time.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| AMQ Clients | json-smart | Not affected | ||
| A-MQ Clients 2 | json-smart | Not affected | ||
| Logging Subsystem for Red Hat OpenShift | json-smart | Not affected | ||
| Red Hat build of Apache Camel 4 for Quarkus 3 | quarkus-cxf-bom | Not affected | ||
| Red Hat build of Apicurio Registry 2 | json-smart | Affected | ||
| Red Hat build of Apicurio Registry 3 | json-smart | Not affected | ||
| Red Hat build of Debezium 2 | json-smart | Affected | ||
| Red Hat build of OptaPlanner 8 | json-smart | Not affected | ||
| Red Hat Data Grid 8 | json-smart | Will not fix | ||
| Red Hat Fuse 7 | json-smart | Out of support scope |
Показывать по
Дополнительная информация
Статус:
EPSS
7.5 High
CVSS3
Связанные уязвимости
A security issue was found in Netplex Json-smart 2.5.0 through 2.5.1. When loading a specially crafted JSON input, containing a large number of ’{’, a stack exhaustion can be trigger, which could allow an attacker to cause a Denial of Service (DoS). This issue exists because of an incomplete fix for CVE-2023-1370.
A security issue was found in Netplex Json-smart 2.5.0 through 2.5.1. When loading a specially crafted JSON input, containing a large number of ’{’, a stack exhaustion can be trigger, which could allow an attacker to cause a Denial of Service (DoS). This issue exists because of an incomplete fix for CVE-2023-1370.
A security issue was found in Netplex Json-smart 2.5.0 through 2.5.1. ...
Netplex Json-smart Uncontrolled Recursion vulnerability
EPSS
7.5 High
CVSS3